Abhishek Kumar created RANGER-5807:
--------------------------------------

             Summary: Configured super-users are incorrectly treated as auditor 
users and denied user-management operations
                 Key: RANGER-5807
                 URL: https://issues.apache.org/jira/browse/RANGER-5807
             Project: Ranger
          Issue Type: Bug
          Components: Ranger
            Reporter: Abhishek Kumar


A user configured through "ranger.admin.super.users" in ranger-admin-site.xml 
receives HTTP 403 when updating another user’s role using:

POST /service/xusers/ugsync/users

relevant stack trace:
{code:java}
2026-09-23T23:06:25Z INFO  org.apache.ranger.biz.SessionMgr: 
[http-nio-6080-exec-7]: Granted full admin privileges via config for user 
spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin
2026-09-23T23:06:25Z INFO  org.apache.ranger.common.RESTErrorUtil: 
[http-nio-6080-exec-7]: Request failed. 
loginId=spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin,
 logMessage=Operation denied. LoggedInUser=9 ,isn't permitted to perform the 
action.
javax.ws.rs.WebApplicationException: HTTP 403 Forbidden
        at 
org.apache.ranger.common.RESTErrorUtil.generateRESTException(RESTErrorUtil.java:71)
        at 
org.apache.ranger.biz.RangerBizUtil.blockAuditorRoleUser(RangerBizUtil.java:1271)
        at 
org.apache.ranger.biz.XUserMgr.createOrUpdateXUsers(XUserMgr.java:2830)
        at 
org.apache.ranger.biz.XUserMgr$$FastClassBySpringCGLIB$$57c6d473.invoke(<generated>)
        at 
org.springframework.cglib.proxy.MethodProxy.invoke(MethodProxy.java:218)
        at 
org.springframework.aop.framework.CglibAopProxy.invokeMethod(CglibAopProxy.java:386)
        at 
org.springframework.aop.framework.CglibAopProxy.access$000(CglibAopProxy.java:85)
        at 
org.springframework.aop.framework.CglibAopProxy$DynamicAdvisedInterceptor.intercept(CglibAopProxy.java:703)
        at 
org.apache.ranger.biz.XUserMgr$$EnhancerBySpringCGLIB$$eecff6cc.createOrUpdateXUsers(<generated>)
        at 
org.apache.ranger.rest.XUserREST.addOrUpdateUsers(XUserREST.java:1414)
        at 
org.apache.ranger.rest.XUserREST$$FastClassBySpringCGLIB$$b2a65360.invoke(<generated>)
        at 
org.springframework.cglib.proxy.MethodProxy.invoke(MethodProxy.java:218)
{code}
The session is correctly recognized as a super-user:
{code:java}
2026-09-23T23:06:25Z INFO  org.apache.ranger.biz.SessionMgr: 
[http-nio-6080-exec-7]: Granted full admin privileges via config for user 
spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin
{code}
However, the request fails in:
{code:java}
2026-09-23T23:06:25Z INFO  org.apache.ranger.common.RESTErrorUtil: 
[http-nio-6080-exec-7]: Request failed. 
loginId=spiffe://demo-tkj.awcqe2.sandbox21.xyz.com/ns/demo-tkj-u-clone-test/sa/ranger-admin,
 logMessage=Operation denied. LoggedInUser=9 ,isn't permitted to perform the 
action.
javax.ws.rs.WebApplicationException: HTTP 403 Forbidden
        at 
org.apache.ranger.common.RESTErrorUtil.generateRESTException(RESTErrorUtil.java:71)
{code}
 

UserSessionBase.isAuditUserAdmin() and isAuditKeyAdmin() return true for every 
configured super-user, causing blockAuditorRoleUser() to reject the operation.

Expected: Configured super-users can update user roles.

Actual: The operation is rejected with HTTP 403.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to